Check Package Vulnerabilities From an AI Agent
Before an agent installs or recommends a dependency, it can check whether that package has known vulnerabilities — using Security Intel, a keyless MCP server backed by the NVD and OSV.
How
- Ask your agent to audit a
package.json— it callsaudit_dependenciesand flags every package with a known CVE. - Or check one package with
package_vulnerabilities, or a specific CVE withcve_lookup.
claude mcp add --transport http security-intel https://security.datakoot.com/mcpPricing
Free on every server — 100 keyless calls a day, no signup. Pro is $15/mo for unlimited, and Team is $49/mo for up to 5 seats — one key unlocks all nine Datakoot servers. See pricing →